6.9

CVSS4.0

CVE-2026-29059 - Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". The filename paramet…

πŸ“… Published: March 6, 2026, 7:11 a.m. πŸ”„ Last Modified: April 15, 2026, 8 p.m.

9.8

CVSS3.1

CVE-2026-29058 - AVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.php

AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full server compromise, data exfiltration (e.g., configuration se…

πŸ“… Published: March 6, 2026, 7:08 a.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

4.3

CVSS3.1

CVE-2026-29049 - melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI

melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cau…

πŸ“… Published: March 6, 2026, 7:03 a.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

6.9

CVSS4.0

CVE-2026-29048 - HumHub: XSS in Button component

HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identified in the Button component of version 1.18.0. Due to inconsistent output encoding at several points within the software, malicious scripts could be injected and executed in the co…

πŸ“… Published: March 6, 2026, 6:59 a.m. πŸ”„ Last Modified: April 17, 2026, 12:30 p.m.

8.9

CVSS4.0

CVE-2026-29042 - Nuclio Shell Runtime Command Injection Leading to Privilege Escalation

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a command injection vulnerability in how it processes user-supplied arguments. When a function is invoked via HTTP, the runtime reads the X-Nuclio-Argum…

πŸ“… Published: March 6, 2026, 6:57 a.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

8.8

CVSS4.0

CVE-2026-29065 - changedetection.io: Zip Slip vulnerability in the backup restore functionality

changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore functionality allows arbitrary file overwrite via path traversal in uploaded ZIP archives. This issue has been patched in version 0.54.4.

πŸ“… Published: March 6, 2026, 6:54 a.m. πŸ”„ Last Modified: April 17, 2026, 12:30 p.m.

8.8

CVSS4.0

CVE-2026-29039 - changedetection.io: XPath - Arbitrary File Read via unparsed-text()

changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io application allows users to specify XPath expressions as content filters via the include_filters field. These XPath expressions are processed using the elementpath library which …

πŸ“… Published: March 6, 2026, 6:54 a.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

6.1

CVSS3.1

CVE-2026-29038 - changedetection.io: Reflected XSS in RSS Tag Error Response

changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected cross-site scripting (XSS) vulnerability identified in the /rss/tag/ endpoint of changedetection.io. The tag_uuid path parameter is reflected directly in the HTTP response body wit…

πŸ“… Published: March 6, 2026, 6:53 a.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

6.9

CVSS4.0

CVE-2026-28804 - pypdf: Inefficient decoding of ASCIIHexDecode streams

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.

πŸ“… Published: March 6, 2026, 6:46 a.m. πŸ”„ Last Modified: April 16, 2026, 11:45 a.m.

7.7

CVSS4.0

CVE-2026-28802 - Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code…

πŸ“… Published: March 6, 2026, 6:44 a.m. πŸ”„ Last Modified: April 16, 2026, 11:45 a.m.
Total resulsts: 349182
Page 1280 of 34,919
Β« previous page Β» next page
Filters